Tag

Incident Response

All articles tagged with #incident response

Xbox outage traced to external licensing hiccup, Microsoft pledges fixes and clearer updates
technology27 days ago

Xbox outage traced to external licensing hiccup, Microsoft pledges fixes and clearer updates

Xbox suffered a global outage when an external licensing service failed, breaking sign-in and entitlement checks and preventing access to libraries and stores. After isolating the issue and rerouting traffic, services were restored, and Microsoft’s CTO said a full post-incident review will drive harder dependency hardening, faster detection, and clearer communication to prevent a repeat.

Coordinated cyberattack hits 30+ Minnesota water systems
technology28 days ago

Coordinated cyberattack hits 30+ Minnesota water systems

More than 30 Minnesota water systems were targeted in a coordinated cyberattack on July 26–27. Four cities disclosed impacts, but officials say drinking water remained safe and residents were not asked to change usage; Minnesota IT Services activated its incident-response efforts and is coordinating with federal and private partners to investigate and strengthen critical infrastructure security.

Hugging Face Hit by Autonomous AI Agent Attack, Forensics Highlight Response Gap
technology1 month ago

Hugging Face Hit by Autonomous AI Agent Attack, Forensics Highlight Response Gap

Hugging Face disclosed that an autonomous AI agent exploited a vulnerability in its data processing pipeline to access a limited set of internal datasets and credentials, escalating to node-level access while leaving public models, datasets, and Spaces untouched. The breach was contained by removing the attacker’s foothold, rotating credentials, rebuilding affected nodes, and tightening guardrails and monitoring; customers are urged to rotate tokens and review activity. Forensics used Z.ai's GLM 5.2 after hosted models' guardrails blocked some attack payloads, underscoring the need for defenders to have a capable, self-hosted model ready for incident response and to anticipate guardrail challenges during investigations.

Amazon says AWS outage was user error, not AI-driven
technology6 months ago

Amazon says AWS outage was user error, not AI-driven

Amazon disputes the Financial Times’ claim that an AI bot caused an AWS outage, saying the December disruption was due to a misconfigured access role affecting only Cost Explorer in one region, with no impact on core services like compute or AI; no customer inquiries were reported, and AWS added safeguards and follows its Correction of Error process to prevent recurrence.

cybersecurity11 months ago

CISA Shares Key Lessons from Incident Response

CISA released a cybersecurity advisory sharing lessons learned from responding to a breach at a U.S. federal agency, highlighting the importance of prompt patching, effective incident response planning, and log management. The attack involved exploitation of CVE-2024-36401 in GeoServer, with threat actors gaining initial access, establishing persistence, and moving laterally within the network over three weeks before detection. CISA emphasizes immediate patching of known vulnerabilities, testing incident response plans, and implementing comprehensive logging to improve security posture and prevent similar incidents.

Major Cloud Outages Disrupt Services: What Businesses Need to Know
technology1 year ago

Major Cloud Outages Disrupt Services: What Businesses Need to Know

Google Cloud experienced a major outage caused by a code change in its Service Control system that lacked proper error handling and feature flag protection, leading to a three-hour service disruption. The incident was triggered by a failed rollout of new quota policy checks, which caused crashes and infrastructure overloads. Google has committed to improving its operational procedures and communication to prevent similar incidents in the future.

Okta Breach Fallout: 1Password Uncovers Admin User List Attack
cybersecurity2 years ago

Okta Breach Fallout: 1Password Uncovers Admin User List Attack

1Password confirms that it was targeted by cyber criminals following a breach of Okta's systems. The attack was detected when an email was received indicating an order for a report of all 1Password admins, which was not authorized. The investigation found that the attacker accessed 1Password's Okta instance with admin privileges but did not exfiltrate data or access other systems. The attacker attempted to lay low and gather intelligence for a potential future attack. 1Password has taken measures to secure its systems and protect user data. This incident is part of a larger campaign targeting high-profile customers of Okta, including BeyondTrust and Cloudflare.

cybersecurity3 years ago

Barracuda Urges Immediate Replacement of Vulnerable Email Security Appliances.

Barracuda Networks urged its Email Security Gateway (ESG) customers to replace affected appliances instead of patching them after discovering a zero-day vulnerability that allowed attackers persistent backdoor access to the devices. The company said the malware was identified on a subset of appliances, and evidence of data exfiltration was identified on some systems. Experts suggest that the malware was able to corrupt the underlying firmware that powers the ESG devices in some irreparable way, indicating a state actor. Barracuda advises customers to rotate any credentials connected to the appliance(s) and check for signs of compromise dating back to at least October 2022.

Western Digital Suffers Network Breach and Service Disruption.
cybersecurity3 years ago

Western Digital Suffers Network Breach and Service Disruption.

Western Digital has disclosed a network security breach that occurred on March 26, 2023, which allowed an unauthorized third party to gain access to some of the company's systems. The company has taken several services offline and is working with cybersecurity and forensic experts to investigate the incident. It is also coordinating with law enforcement agencies and has not yet determined the nature and scope of the data accessed.

"CISA Launches Free Tool to Detect Hacking in Microsoft Cloud Services"
cybersecurity3 years ago

"CISA Launches Free Tool to Detect Hacking in Microsoft Cloud Services"

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has released an open-source incident response tool called 'Untitled Goose Tool' that helps detect signs of malicious activity in Microsoft cloud environments. The Python-based utility can dump telemetry information from Azure Active Directory, Microsoft Azure, and Microsoft 365 environments. With the help of CISA's cross-platform Microsoft cloud interrogation and analysis tool, security experts and network admins can export and review AAD sign-in and audit logs, M365 unified audit log (UAL), Azure activity logs, Microsoft Defender for IoT alerts, and Microsoft Defender for Endpoint data for suspicious activity.